Security Headers

io.github.basitalisandhuv0.1.1Updated Oct 5, 2026

Fetch a URL's response headers and grade CSP, HSTS, X-Frame-Options and related security headers.

Overview

AI-generated overview

Fetches a public URL's HTTP response headers and grades its security headers, with per-header explanations and recommendations.

What it does
The server exposes three tools. check_url_headers sends a HEAD request (falling back to GET on 405/501) to a public http(s) URL, follows redirects and grades the security headers on every hop. grade_headers applies the same grading to header sets you already have, without any network access. explain_header returns the purpose, recommended value and reference for a single header. Grading covers CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, the Cross-Origin-* headers, Set-Cookie attributes and information-disclosure headers, producing a score and a letter grade.
When to use it
Useful when you want an assistant to audit the security headers of a site you own or are reviewing, to compare headers captured elsewhere, or to look up what a specific header should be set to. It is a configuration check, not a penetration test.
Requirements
Runs locally over stdio as an npm package (npx @basitalisandhu/mcp-security-headers) or as an OCI image via Docker; Node.js is needed for the npm route. No accounts, API keys or environment variables are declared. Network access is required for check_url_headers; grade_headers and explain_header work offline. Desktop clients only.
Before you install
check_url_headers makes outbound requests to the URL you supply and follows redirects, so only point it at hosts you trust; the README notes that host validation does not defeat DNS rebinding between the check and the connection. The response body is never downloaded and no telemetry is sent. A good grade reflects header configuration only, not overall application security.

Installation

In SourceWeft

  1. Open Security Headers in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

security-headers MCP server

Fetches a public URL's response headers and grades Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, the Cross-Origin-* headers, Set-Cookie attributes and information-disclosure headers, with an explanation and a recommendation per header. The response body is never downloaded.

Part of dev-mcp-servers. Stdio transport only; the server never opens a port.

Tools

ToolInputWhat it returns
check_url_headersurl, method? (HEAD or GET), max_redirects? (0 to 10, default 5)HEAD request (GET on 405/501) to a public http(s) URL, redirects followed with the same checks on every hop, then a graded report. Refuses localhost, .local, .internal, private, loopback, link-local, CGNAT and cloud-metadata addresses, including names that resolve to them.
grade_headersheaders (object), https?The same grading for headers you already have, for example from curl -I. No network.
explain_headerheaderPurpose, recommended value and reference for one header.

Install

Claude Code:

bash
claude mcp add security-headers -- npx -y @basitalisandhu/[email protected]

Add -s user to make it available in every project. Any client that reads .mcp.json (Claude Code, Claude Desktop, Cursor):

json
{  "mcpServers": {    "security-headers": {      "command": "npx",      "args": ["-y", "@basitalisandhu/[email protected]"]    }  }}

Pin the version as shown so that an update to the package cannot change what runs in your editor without you noticing. From a checkout, use "command": "node", "args": ["<path>/packages/security-headers/dist/index.js"] after npm install && npm run build at the repository root.

What it touches

  • Network: One request to the URL you give plus at most max_redirects hops, each validated. 10 s timeout per request. The host is resolved and every address checked before connecting; this does not defeat DNS rebinding between the check and the connection, so do not point the tool at hosts you do not trust to answer honestly. No telemetry.
  • Local files: None.
  • Telemetry: none.

Notes

  • Scores: CSP 25, HSTS 20, X-Frame-Options 10, X-Content-Type-Options 10, Referrer-Policy 10, Set-Cookie 10, Permissions-Policy 5, COOP 5, CORP 5. Grades: A+ (95% and no fail), A (85% and no fail), B (70%), C (55%), D (40%), otherwise F.
  • A report-only CSP earns nothing: it is not enforced.
  • A good grade means the headers are configured well, not that the application is secure.

Build and test

bash
npm install        # at the repository rootnpm run build -w @basitalisandhu/mcp-security-headersnpm test -w @basitalisandhu/mcp-security-headers

Tests use node:test and the SDK's in-memory transport; they do not reach the network.

Licence

MIT. See LICENSE.

Source: packages/security-headers/README.md at commit 58c8c95

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.1.1LatestOct 5, 2026